{
  "id": 6268923,
  "title": "BigBear 2.0 phishing campaign hijacks Microsoft 365 sessions after MFA",
  "url": "https://urgent.news/2026/09/08/bigbear-2-0-phishing-campaign-hijacks-microsoft-365-sessions-after-mfa",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-08T10:54:59.000Z",
  "source": {
    "name": "Computerworld",
    "slug": "computerworld",
    "url": "https://www.computerworld.com/article/4219614/bigbear-2-0-phishing-campaign-hijacks-microsoft-365-sessions-after-mfa-2.html"
  },
  "original_language": "en",
  "account": "A phishing campaign known as BigBear 2.0 has been stealing Microsoft 365 session cookies, potentially allowing attackers to hijack authenticated sessions after victims complete multi-factor authentication, according to a report by CloudSEK. The operation, which targeted more than 40 countries across 461 organizations, harvested 4,148 session cookies and 1,032 plaintext passwords. The phishing-as-a-service campaign, built on Evilginx2, intercepts authenticated session cookies issued after MFA to enable unauthorized access. Researchers found that the operation also disables FIDO2/WebAuthn authentication on phishing pages, potentially steering users towards weaker authentication methods. Enterprises need to move beyond protecting the authentication event itself and consider stolen session cookies and access and refresh tokens as high-value authentication material. Phishing-resistant authentication methods, such as FIDO2/WebAuthn passkeys, should be enforced as primary defenses against this type of attack.",
  "summary": "A phishing-as-a-service operation targeting Microsoft 365 users has harvested thousands of session cookies that could be used to hijack authenticated sessions after victims complete multifactor authentication, CloudSEK said. The cybersecurity firm said in a report that it uncovered the operation, known as BigBear 2.0, in June after gaining access to its administrative panel. The panel contained…",
  "key_points": [
    "BigBear 2.0 phishing campaign steals Microsoft 365 session cookies",
    "Attackers can hijack authenticated sessions after MFA completion",
    "Phishing-as-a-service campaign disables FIDO2/WebAuthn authentication"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "BigBear phishing crew nets thousands of Microsoft 365 credentials",
        "url": "https://urgent.news/2026/09/08/bigbear-phishing-crew-nets-thousands-of-microsoft-365-credentials",
        "published": "2026-09-08T13:26:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}